HackerFeeds

CyberSecurity News

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

The Hacker News
· September 17, 2026

AI summary

Cisco has identified a severe security flaw in its Identity Services Engine that is being actively exploited. The vulnerability allows an unauthenticated remote attacker to bypass authentication due to insufficient control on an API endpoint. This flaw has a CVSS score of 10.0, indicating a maximum severity level. Cisco has assigned the vulnerability the identifier CVE-2026-76460. The issue makes it possible for an attacker to gain unauthorized access without proper authentication. An attacker can exploit this vulnerability remotely.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.